Skip to main content
Vault access applies to its whole file tree. A folder is not an independent membership boundary. Local synchronization additionally requires the vault’s local-sync policy and the connection’s grants. A connection can never exceed the current access of its owner.

Grant a vault role

  1. Open Knowledge and select the vault.
  2. Open the vault-root context menu and its access controls.
  3. Select an active person or agent and assign Viewer, Editor, or Vault admin.
  4. For company and team vaults, you can also assign a group.
  5. Have the recipient reopen the workspace and check the vault.
You need Vault admin access to manage these grants. Removing one grant may not remove access if the person still has a stronger role through another group or organization administration.

Workspace roles and vault roles

Workspace owners and admins implicitly administer company and team vaults. Ordinary members need direct or group-derived grants. The highest effective vault role wins. Personal vaults are different: only their owner and explicitly granted people or agents receive access. Workspace administration alone gives no personal-vault access. Groups cannot receive personal-vault grants, and the owner’s grant cannot be removed or demoted. A delegated personal vault admin can manage other non-owner grants.

Local-sync policy

A vault admin can disable local sync. This prevents authorized replica access going forward; it does not erase previously downloaded files. Remote MCP read/write access is separate from local sync and must be managed through its connection grants. For read-only access to a particular subtree without a vault membership, review share links.